Skip to main content

Uppercase Expanding Length in String Fields

ItemDescription
Full Fuzzer NameUppercaseExpandingLengthInStringFieldsFuzzer
Log KeyUELISF
DescriptionThis fuzzer send characters that expand their length when upper cased. The expectation is that APIs will either respond with 2xx or 4xx.
Enabled by default?Yes
Target field typesAll array fields
Expected result when fuzzed field is required2XX or 4XX
Expected result when fuzzed field is optional2XX or 4XX
Expected result when fuzzed value is not matching field pattern2XX or 4XX
Fuzzing logicIteratively replaces string fields with characters such as ß, , , etc.
Conditions when this fuzzer will be skippedWhen field is not a string
HTTP methods that will be skippedNone
ReportingReports error if: 1. response code is 5xx;

Reports warn if: 1. response code is expected and documented, but not matches response schema; 2. response code is expected, but not documented; 3. response code is 501.

Reports success if: 1. response code is expected, documented and matches response schema.